CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2023-22401 HIGH
Juniper Networks Junos OS/Junos OS Evolved - DoS
CVSS 7.5
CVE-2022-50315 HIGH
Linux Kernel Array Index Out-of-Bounds in AHCI EM Priv Array
CVSS 7.8
CVE-2022-50066 HIGH
Linux Kernel 4.11-5.19.3 - Out-of-Bounds Array Index in aq_nic_stop
CVSS 7.8
CVE-2022-49720 HIGH
Linux Kernel 4.16-5.10.213, 5.11-5.15.48, 5.16-5.18.5 - Out-of-Bounds Array Index in blk_mq_alloc_request_hctx
CVSS 7.8
CVE-2022-49548 HIGH
Linux Kernel 5.7-5.10.119, 5.11-5.15.44, 5.16-5.17.12, 5.18 - Memory Corruption via BPF Trampoline Array Overflow
CVSS 7.8
CVE-2022-49478 HIGH
Linux kernel - Array Index Out-of-Bounds
CVSS 7.8
CVE-2022-49471 HIGH
Linux Kernel < 5.17.14, 5.16.0-5.16, 5.18.0-5.18.3 - Out-of-Bounds Array Access in rtw89_phy_cfo_parse
CVSS 7.8
CVE-2022-49186 HIGH
Linux Kernel 5.17-5.17.1 - Out-of-Bounds Array Access in visconti_clk_register_gates()
CVSS 7.8
CVE-2022-49170 HIGH
Linux kernel - Array Index Out of Bounds
CVSS 7.8
CVE-2022-49022 HIGH
Linux Kernel 5.5-5.10.158, 5.11-5.15.82, 5.16-6.0.12 - Out-of-Bounds Array Access in ieee80211_get_rate_duration
CVSS 7.8
CVE-2022-48979 MEDIUM
Linux Kernel < 6.0.13 - Array Index Out-of-Bounds in DCN32 DML
CVSS 5.5
CVE-2022-48967 HIGH
Linux Kernel Out-of-Bounds Write in NFC NCI Target Array Handling
CVSS 7.1
CVE-2022-48883 HIGH
Linux Kernel 5.17-6.1.6 - Out-of-Bounds Access in PKEY Interface Channel Stats
CVSS 7.8
CVE-2022-48702 HIGH
Linux Kernel < 4.9.328 - Out-of-Bounds Array Access in ALSA emu10k1 Voice Allocator
CVSS 7.8
CVE-2022-40534 HIGH
Qualcomm WCN685X-5 Firmware - Memory Corruption in Audio Array Index Validation
CVSS 8.4
CVE-2022-33275 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 8.4
CVE-2022-48503 HIGH KEV
Safari < 15.6 - Remote Code Execution via Array Index Validation Issue
CVSS 8.8
CVE-2022-33281 MEDIUM
Qualcomm WCN685X-5 Firmware - Memory Corruption via Improper Array Index Validation
CVSS 6.7
CVE-2022-33302 MEDIUM
User Identity Module - Memory Corruption
CVSS 6.8
CVE-2022-33289 MEDIUM
Qualcomm Modem Firmware - Memory Corruption via Malformed APDU
CVSS 6.8
CVE-2022-38072 MEDIUM
ADMesh Master Commit <767a105-0.98.4 - Buffer Overflow
CVSS 6.5
CVE-2022-40539 HIGH
Qualcomm Automotive Android OS - Memory Corruption via Improper Array Index Validation
CVSS 8.4
CVE-2022-40537 HIGH
Qualcomm APQ8009 Firmware - Memory Corruption in Bluetooth HOST via AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP Response
CVSS 7.3
CVE-2022-33256 CRITICAL
Qualcomm Multi-mode Call Processor Firmware - Memory Corruption
CVSS 9.8
CVE-2022-47348 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Engineermode Services
CVSS 5.5
Details
Vulnerabilities 604
Exploit Likelihood High